Simple Chat

Release notes

For feature-focused and fix-focused drill-downs by version, see Features by Version and Fixes by Version.

This page includes the latest release notes inline. Older release sections are split into smaller pages by minor series.

Version index

Version Page
v0.261.023 Release notes index
v0.261.021 Release notes index
v0.261.020 Release notes index
v0.261.019 Release notes index
v0.261.018 Release notes index
v0.261.017 Release notes index
v0.261.016 Release notes index
v0.261.015 Release notes index
v0.261.014 Release notes index
v0.261.013 Release notes index
v0.261.012 Release notes index
v0.261.011 Release notes index
v0.261.010 Release notes 0.261 series
v0.261.009 Release notes 0.261 series
v0.261.007 Release notes 0.261 series
v0.261.006 Release notes 0.261 series
v0.261.005 Release notes 0.261 series
v0.261.004 Release notes 0.261 series
v0.261.003 Release notes 0.261 series
v0.261.002 Release notes 0.261 series
v0.261.001 Release notes 0.261 series
v0.260.025 Release notes 0.260 series
v0.260.024 Release notes 0.260 series
v0.260.023 Release notes 0.260 series
v0.260.021 Release notes 0.260 series
v0.260.020 Release notes 0.260 series
v0.260.019 Release notes 0.260 series
v0.260.018 Release notes 0.260 series
v0.260.017 Release notes 0.260 series
v0.260.016 Release notes 0.260 series
v0.260.015 Release notes 0.260 series
v0.260.014 Release notes 0.260 series
v0.260.013 Release notes 0.260 series
v0.260.012 Release notes 0.260 series
v0.260.011 Release notes 0.260 series
v0.260.010 Release notes 0.260 series
v0.260.009 Release notes 0.260 series
v0.260.008 Release notes 0.260 series
v0.260.007 Release notes 0.260 series
v0.260.006 Release notes 0.260 series
v0.260.005 Release notes 0.260 series
v0.260.004 Release notes 0.260 series
v0.260.003 Release notes 0.260 series
v0.260.002 Release notes 0.260 series
v0.260.001 Release notes 0.260 series
v0.250.231 Release notes 0.250 series
v0.250.230 Release notes 0.250 series
v0.250.229 Release notes 0.250 series
v0.250.001 Release notes 0.250 series
v0.241.007 Release notes 0.241 series
v0.241.006 Release notes 0.241 series
v0.241.002 Release notes 0.241 series
v0.241.001 Release notes 0.241 series
v0.239.002 Release notes 0.239 series
v0.237.049 Release notes 0.237 series
v0.237.011 Release notes 0.237 series
v0.237.009 Release notes 0.237 series
v0.237.007 Release notes 0.237 series
v0.237.006 Release notes 0.237 series
v0.237.005 Release notes 0.237 series
v0.237.004 Release notes 0.237 series
v0.237.003 Release notes 0.237 series
v0.237.001 Release notes 0.237 series
v0.235.025 Release notes 0.235 series
v0.235.012 Release notes 0.235 series
v0.235.003 Release notes 0.235 series

Latest release notes

(v0.261.023)

New Features

  • XSD Ingestion and Schema-Validated XML Generation
    • Added .xsd ingestion for personal, group, public, chat-upload, generated-artifact promotion, and File Sync paths when Enhanced Citations storage is available.
    • Preserves exact schema bytes in immutable Blob locations and indexes one bounded metadata summary instead of fragmenting the schema as narrative content.
    • Resolves same-workspace includes and imports, tracks schema readiness, and revalidates dependent schemas when current revisions change.
    • Uses an explicitly selected ready XSD as the authoritative contract for XML generated by Chat, Analyze, agents, and Analyze workflows, with whole-document validation before publication.
    • Implements the fail-closed simplechat-xsd10-subset-profile/1; unsupported XSD 1.1 and other excluded constructs are retained with diagnostics but cannot govern generation.
    • (Ref: #1212, XSD ingestion, mixed-source orchestration, schema-bound XML artifacts, functions_xsd_schema.py, functions_documents.py)

Bug Fixes

  • XSD Upload Errors Use Allowlisted Browser Responses
    • Replaced exception-derived chat-upload responses with an explicit allowlist of stable XSD error codes, messages, and HTTP statuses.
    • Unknown XSD ingestion failures now return a generic error without exposing exception details.
    • (Ref: route_frontend_chats.py, XSD upload error handling)

(v0.261.021)

Bug Fixes

  • OAuth2 Token Endpoints Are Now Validated When The Token Is Fetched
    • A Custom endpoint’s OAuth2 token URL was checked when the endpoint was saved, but not when the token was actually requested. Validating only at save time leaves the request itself unguarded, since settings can be written by another path, restored from backup, or changed after validation. Code scanning correctly identified this as a server-side request forgery.
    • The token URL is now revalidated at request time against the same outbound policy as the inference endpoint, and the request runs on the same pinned transport, so its addresses are validated at connection time and redirects are refused.
    • Refusing redirects is safe for this grant: redirects belong to the browser-based authorization-code flow, whereas a client-credentials token endpoint answers a server-to-server POST with a JSON body. The previous code allowed them based on an incorrect assumption.
    • (Ref: functions_model_endpoint_auth.py, #1437)
  • Endpoint URL Version Matching No Longer Backtracks
    • The pattern recognising a version path segment allowed its optional suffix to begin with a digit, making it ambiguous with the preceding digits and quadratic on a long run of them. A 8,000-character segment took roughly 0.19 seconds to reject; it now takes 0.0003 seconds.
    • The suffix must now begin with a letter, which removes the ambiguity while matching exactly the same version segments.
    • (Ref: model_endpoint_clients.py, #1437)

(v0.261.020)

New Features

  • Custom Model Endpoints Support Bearer Tokens, OAuth2, And Client Certificates
    • Custom endpoints accepted one authentication scheme: an API key sent in whichever header the built-in providers happened to use. That covers OpenAI and Anthropic and nothing else, so a gateway expecting x-goog-api-key, a corporate gateway issuing short-lived tokens, and an appliance requiring a client certificate were all unreachable.
    • The API key header name and value prefix are now configurable, so a single scheme covers Authorization: Bearer, Anthropic’s x-api-key, Google’s x-goog-api-key, and any bespoke gateway header.
    • Added static bearer token authentication.
    • Added OAuth2 client credentials, with token caching and refresh ahead of expiry so a token cannot lapse mid-request. The token endpoint is validated against the same outbound policy as the inference endpoint, so it cannot become an unchecked request target, and a failing token response is sanitized before it reaches the browser.
    • Added mTLS client certificates. Certificates are referenced by file path so a private key is mounted into the deployment and never written to the configuration database.
    • (Ref: functions_model_endpoint_auth.py, functions_model_endpoint_providers.py, functions_model_endpoint_validation.py, #1228)

(v0.261.019)

New Features

  • On-Premises Custom Model Endpoints Now Work
    • The administrator gate named “allow private Custom endpoint hosts” did not actually permit the two most common on-premises address forms. An IP address such as https://10.20.30.40/v1 and a short host name such as https://llm-gateway/v1 were both rejected even with the gate enabled, and both were refused with a message claiming the URL was an IP address, which was wrong for the short host name.
    • With the gate enabled, IP addresses, short host names, and hosts resolving to private ranges are now accepted. Loopback, link-local, and cloud metadata addresses remain rejected regardless of any setting, and every address is still revalidated at connection time.
    • Added a CA bundle setting. Custom endpoints trust only public certificate authorities and deliberately ignore ambient environment variables, so an on-premises gateway using an internally issued certificate previously could not be trusted at all. An administrator can now name a PEM bundle. A bundle that cannot be loaded fails loudly rather than silently falling back to weaker trust.
    • Added a separate plaintext HTTP gate for isolated networks where TLS cannot be terminated. It requires the private-hosts gate as well, and is labelled with its consequence: prompts and API keys travel unencrypted.
    • Saving an endpoint no longer requires the host name to resolve from the application tier, so configuration can be seeded or restored from backup ahead of connectivity. Policy violations are still refused at save time, and the connection-time check is unchanged.
    • (Ref: functions_model_endpoint_validation.py, model_endpoint_clients.py, allow_insecure_custom_model_endpoints, custom_model_endpoint_ca_bundle_path, #1228)

(v0.261.018)

Bug Fixes

  • Tool-Calling Responses Now Actually Stream
    • SimpleChat only supports streaming responses, but tool calling cannot stream, because a tool call has to arrive whole. The completed answer was delivered through the streaming interface as a single chunk, so the user saw nothing at all and then the entire response at once, which reads as a hang. Because agents and plugins rely on tool calling, this was a common path rather than an edge case.
    • A completed answer is now split into chunks at word boundaries and delivered progressively, so it reads like a real stream. Chunking is lossless — the reassembled text is byte-for-byte identical.
    • Tool calls still arrive whole, on the final chunk, alongside the finish reason and usage metadata. Emitting metadata once means token usage is no longer at risk of being counted per chunk.
    • Streaming responses can report token usage again. stream_options was stripped from every OpenAI-compatible request, which suppressed usage reporting for all of them. It is now dropped only for surfaces that reject it.
    • (Ref: model_endpoint_clients.py, functions_model_endpoint_providers.py, #1228)

(v0.261.017)

Bug Fixes

  • Custom Endpoint URLs Are No Longer Rewritten Into 404s
    • SimpleChat appended /v1 to every Custom OpenAI-compatible endpoint, even when the configured URL already said where the API lived. A gateway at https://apim.example.com/inference/chat/completions was called at https://apim.example.com/inference/v1/, and any base carrying its own version segment, such as /v1beta or /v2, was broken the same way.
    • /v1 is now appended only when the URL does not already name the API surface. A path whose last segment is a version is left alone, and a full operation URL is treated as stating the base exactly.
    • Added a Use this URL exactly as entered option for gateways that serve the API at a path SimpleChat cannot infer.
    • Test Connection now reports the URL that was actually called. URL normalization rewrites the configured endpoint, and that rewrite was previously invisible, so a misdirected request looked identical to a correct one.
    • (Ref: model_endpoint_clients.py, route_backend_models.py, _multiendpoint_modal.html, admin_model_endpoints.js, workspace_model_endpoints.js, #1228)

(v0.261.016)

Bug Fixes

  • Custom Model Endpoint Failures Are Now Diagnosable
    • Every Custom endpoint failure produced the same sentence — “Custom model request failed.” — with the underlying cause discarded before it reached the log. A wrong path, a wrong API key, a wrong model name, a TLS failure, and a blocked address were indistinguishable, and nothing anywhere explained which had happened.
    • The browser message stays sanitized, because an upstream error body can echo back a URL, a header, or an API key. The real cause is now recorded server-side with the API type, the resolved request URL, the upstream status code, and the upstream error body.
    • Both the message and the log entry now carry a short reference id, so an administrator can join the message a user reports to the log entry that explains it.
    • Credentials are redacted before anything is written to the log, covering API keys, bearer tokens, x-api-key, x-goog-api-key, and key query parameters. A logging failure never replaces the original error.
    • The resolved request URL is included deliberately: URL normalization can rewrite what the administrator typed, and that rewrite was previously invisible.
    • (Ref: functions_model_endpoint_diagnostics.py, model_endpoint_clients.py, functions_model_endpoint_runtime.py, #1228)

(v0.261.015)

New Features

  • Custom Model Endpoints Now Support Google Gemini, Through A Provider Registry
    • Custom endpoints supported exactly three API types, and each one was hard-coded in five separate places: the allowlist, the request-model resolver, the protocol inference chain, the admin template’s option list, and the admin JavaScript. Adding a provider meant editing all five and hoping none were missed.
    • An API type is now a single declarative registry entry that carries its wire protocol, which field names the model, how its URL is built, which authentication types it accepts, and which version field applies. The admin API Type list, the model identifier label, and the version fields all render from that registry.
    • Google Gemini is now selectable as a Custom endpoint API type, reached through its OpenAI-compatible surface so it still runs on SimpleChat’s validated-DNS pinned transport.
    • Fixed URL handling for endpoints that already carry a version segment. SimpleChat appended /v1 unconditionally, which turned Gemini’s …/v1beta/openai base into …/v1beta/openai/v1 and produced a 404. URL construction is now per-provider, so /v1 is appended only where it belongs.
    • The three existing API types are unchanged, and an unregistered API type is still refused.
    • (Ref: functions_model_endpoint_providers.py, functions_model_endpoint_types.py, model_endpoint_clients.py, admin_model_endpoints.js, workspace_model_endpoints.js, _multiendpoint_modal.html, #1228)

(v0.261.014)

New Features

  • Model Capabilities Now Come From The Model Catalog Instead Of The Model’s Name
    • SimpleChat previously worked out what a model could do by pattern-matching its name, so a model the catalog did not know about — an on-premises or customer-supplied model reached through a Custom endpoint — silently received wrong answers for vision, tool calling, streaming, and reasoning. A model named corp-llm-v2 was treated as having no capabilities at all.
    • Capability answers now resolve through a precedence chain: a per-model override, then an endpoint-level override, then the shipped model catalog, then the original name heuristics. Administrators can describe a model the catalog has never heard of without waiting for a catalog update, and models absent from the catalog behave exactly as before.
    • The catalog gained supportsStreaming and reasoning flags for every model, and now covers Google Gemini, which had no entries at all. Claude, Llama 4, and Phi-4 multimodal models are correctly recognised as vision-capable for the first time; the -chat variants of the GPT-5.x families are correctly recognised as not vision-capable.
    • The catalog is now validated against a published JSON schema, so a malformed or incomplete model record fails a test rather than silently degrading capability answers at runtime.
    • (Ref: functions_model_capabilities.py, model_capabilities.json, model_capabilities.schema.json, MODEL_CAPABILITY_CATALOG.md, #1228)

(v0.261.013)

New Features

  • Custom Model Endpoint Provider
    • Added manually configured Custom endpoints for OpenAI API, Azure OpenAI API, and Anthropic chat models across global, personal, and group scopes.
    • Added type-specific model identifiers, API-key authentication, connection testing, response-length controls, and Anthropic Version support without model discovery.
    • Enforced HTTPS, DNS/address safety with connection-time address pinning, runtime URL revalidation, redirect refusal, Key Vault secret handling, and an administrator-controlled private-host policy.
    • (Ref: #1222, Custom model endpoints, functions_model_endpoint_runtime.py, _multiendpoint_modal.html, CUSTOM_MODEL_ENDPOINT_PROVIDER.md)

(v0.261.012)

New Features

  • Yamcs Actions Can Reach Servers Behind An Authenticating Proxy
    • Ground segments commonly publish Yamcs through a reverse proxy, such as Apache, that challenges every request with HTTP Basic authentication against a directory before the request reaches Yamcs. Yamcs behind that proxy often has no authentication of its own. Until now a Yamcs action could not answer that challenge, so such a server was unreachable even when the Yamcs settings were correct.
    • A new Reverse Proxy Authentication option on the Yamcs action sends an HTTP Basic Authorization header on every request. It is off by default, so a Yamcs server reached directly, such as a local simulator, is unaffected.
    • The proxy credential can be typed on the action, with the password stored in Key Vault, or supplied by a reusable username and password identity. Where a directory issues temporary passwords, the identity is rotated once under Workspace → Identities and every action that references it picks up the new password without being edited.
    • The proxy credential has its own identity reference, separate from the Yamcs credential, so one action can use both.
    • Proxy authentication combines with the No Authentication and API Key Yamcs methods. It cannot combine with Username and Password or Access Token, because only one Authorization header can be sent and the Yamcs token request would itself be refused by the proxy. The conflict is reported when saving the action and when running Test Yamcs Connection rather than failing later at run time.
    • Test Yamcs Connection exercises the proxy credential and distinguishes a proxy rejection from a Yamcs rejection.
    • (Ref: functions_yamcs_operations.py, yamcs_plugin.py, functions_workspace_identities.py, plugin_health_checker.py, route_backend_plugins.py, _plugin_modal.html, plugin_modal_stepper.js, test_yamcs_basic_auth.py, Yamcs Action, #1435)

(v0.261.011)

Bug Fixes

  • Redis Connection Test No Longer Returns Credential Errors To The Browser
    • Restored the hardening that a refactor had dropped: when the admin Redis connection test fails while resolving credentials, the details are logged under [REDIS_TEST] and the browser receives a generic message instead of the raw exception, which could carry Key Vault secret names, vault URIs, or token details.
    • Validation problems such as a missing host name or access key are still returned directly, because those messages are generated by SimpleChat and are what the admin needs to fix the form.
    • (Ref: route_backend_settings.py, test_redis_client_factory.py)
  • Deployer Redis Kind Detection Matches The Full Host Name Suffix
    • The postprovision fallback that infers the Redis offering from a host name used a substring check, so a host name that merely contained .redis.azure.net anywhere could be misread as Azure Managed Redis and configured with the wrong port.
    • It now matches the full suffix, consistent with the application’s own detection.
    • (Ref: deployers/bicep/postconfig.py)